T06 · System Persistence
- Location
scripts/create_court_calendar.py:75- Finding
Persistent LaunchAgent Is Installed Without Automatic Cleanup
- Content
View full analysis
Label com.mm.court-{uid_hash} ProgramArguments /usr/bin/osascript -e display notification "{notification_text}" with title "Court Hearing Reminder" StartCalendarInterval Hour {start_dt.hour} Minute {start_dt.minute} Month {alarm_dt.month} Day {alarm_dt.day} ''' os.makedirs(os.path.dirname(plist_path), exist_ok=True) with open(plist_path, 'w') as f: f.write(plist_content) subprocess.run(['launchctl', 'load', plist_path], capture_output=True) ``` ### Technical Analysis The script writes a property-list file to the user's `~/Library/LaunchAgents` directory and immediately loads it with `launchctl`. A LaunchAgent is a cross-session persistence mechanism that can run after the original skill invocation has ended. The persistence is related to the advertised reminder functionality, but its lifecycle is unsafe ...[truncated 1619 chars]- Remediation
View remediation
